Model-Based Management of Security Services in Complex Network Environments

De Albuquerque, J. P. , Krumm, H. and De Geus, P. L. (2008) Model-Based Management of Security Services in Complex Network Environments. In: NOMS 2008 - 2008 IEEE Network Operations and Management Symposium, Salvador, Brazil, 07-11 Apr 2008, pp. 1031-1036. ISBN 9781424420650 (doi: 10.1109/NOMS.2008.4575274)

Full text not currently available from Enlighten.

Abstract

The security mechanisms employed in current networked environments are increasingly complex, and their configuration management has an important role for the protection of these environments. Especially in large scale networks, security administrators are faced with the challenge of designing, deploying, maintaining and monitoring a huge number of mechanisms, most of which have complicated and heterogeneous configuration syntaxes. Consequently, configuration errors are nowadays a frequent cause of security vulnerabilities. This paper summarizes results from a doctoral thesis that offers an approach to the configuration management of network security systems specially suited to the needs of the complex environments of today's organizations. The approach relies upon policy-based management and model-based management, extending these approaches with a modeling framework that allows the design of security systems to be performed in a modular fashion. The model is segmented into logical units (so-called Abstract Subsystems) that enclose a group of security mechanisms and other relevant system entities, offering a more abstract representation of them. In this manner, the administrator is able to design a security system-including its different mechanism types and their mutual relations-by means of an abstract and uniform modeling technique. A software tool supports the approach, offering a diagram editor for models. After the model is complete, the tool performs an automated policy refinement, deriving configuration parameters for each security mechanism in the system.

Item Type:Conference Proceedings
Status:Published
Refereed:Yes
Glasgow Author(s) Enlighten ID:Porto de Albuquerque, Professor Joao
Authors: De Albuquerque, J. P., Krumm, H., and De Geus, P. L.
College/School:College of Social Sciences > School of Social and Political Sciences > Urban Studies
Journal Name:NOMS 2008 - IEEE/IFIP Network Operations and Management Symposium: Pervasive Management for Ubiquitous Networks and Services
ISSN:1542-1201
ISBN:9781424420650
Related URLs:

University Staff: Request a correction | Enlighten Editors: Update this record